Cyber Incident Victim: City of Coweta
Timeline
Summary
City of Coweta experienced a system-wide ransomware attack using the Anubis strain that encrypted files, documents and municipal financial systems. Officials refused to pay the ransom and did not engage with the attackers, citing past experience where payment led to reinfection. They confirmed that credit card and payment data stored on a separate cloud service were not accessed and that emergency services remained operational on isolated networks. While contracted IT specialists, cyber insurers, local police and the FBI examined server logs, the city began restoring operations from an offsite backup and planned to upgrade authentication to passkeys. During the outage, water shutoff penalties were suspended and residents could still pay utility bills online or in person.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Wednesday, August 5, 2026, hackers targeted the City of Coweta with a ransomware strain identified as Anubis. The attack encrypted local files, Word documents, Excel spreadsheets, and municipal financial systems across city hall. The attackers delivered ransom notes demanding payment, but city officials chose not to open a line of communication. City Manager Julie Casteen stated that the ransom amount remains unknown because the city is not engaging with the attackers.

City leaders emphasized that credit card and payment information were not compromised, noting that payment processing is handled on an independent cloud server that was not accessed during the breach. They also confirmed that emergency services, including 911 dispatch, the police department, and the fire department, operate on separate offsite networks and remained fully operational throughout the incident. No infiltration was detected onto the city’s payment system, and officials assured residents that citizen payment data remained secure. While the outage persisted, the city suspended water shutoffs for nonpayment and waived late penalties.
Contracted IT professionals, cyber insurance experts, local police, and the FBI began reviewing server logs to determine how the intrusion occurred. In the meantime, the city initiated a restoration effort using an offsite backup, aiming to have all systems fully operational by Monday. Residents were advised that they could still pay utility bills online through Xpress Bill Pay via the city website or by delivering a check to City Hall, with staff onsite to assist those preferring in-person payment. To reduce the risk of future breaches, the city is working to upgrade its internal network security from standard multi-factor authentication to passkeys, and additional updates are expected early next week.
